CVE-2021-40441 is a Windows Media Center Elevation of Privilege vulnerability affecting various versions of Windows 7, 8.1, and Server 2008/2012. With a CVSS score of 7.8 (High), it allows a local, low-privileged attacker to gain high privileges on the system without user interaction. While the vulnerability has a high potential for impact (confidentiality, integrity, and availability), there is no public exploit code available, nor is it listed on the CISA KEV catalog. Community discussion and media coverage are minimal, suggesting low active exploitation or widespread awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
sp1CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:sp1:*:*:*:*:*:x64:* | ||
sp1CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:sp1:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:-:*:-:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.